Suspicious
Suspect

b98f402f5798d1c5f8e5747b6a4ac021

Share on LinkedIn
Print
PE Executable
MD5: b98f402f5798d1c5f8e5747b6a4ac021
Size: 312.58 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 b98f402f5798d1c5f8e5747b6a4ac021
Sha1 e7f384c85cb6d6452a780aff180272fa9a48ee93
Sha256 5479db44591b9eed754dcf392ce1124f535ae6ae23f8e8965fc5f33b70bc7f6c
Sha384 32e0ee187fa302ac22cd8a5c6868f0f2aa61c3b3a6bc4c12a15c8105f03cd8e6003691861dc6c6ba798c04eb8c32b2a6
Sha512 79bfae3c59ef7952140d347a5fc4ea1204ec9ae20d5e8c7bd6c365f2b22a3429ffcbd38415c34304aae14b8aef43abc477f93b713094dd62a1dd9fec4b2f4e2e
SSDeep 6144:1mlfAgiw7Op5ryNkS7Z12wvtGVG3iVt8eZ1u2J/xFji9p:A1iw7gryNkSV1hy1Z1u2JLu9p
TLSH AF647C11B9C48432C673383107B4E2B28DBDB8302D655B8F57A81D7A9F741D0EA29B6F
PeID
MASM/TASM - sig4 (h)Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ 8Microsoft Visual C++ 8Microsoft Visual C++ v6.0 DLLVC8 -> Microsoft Corporation
[Authenticode]_92eae2e1.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x49800 size 11520 bytes
Info
PDB Path: C:\builds\cc\cwcontrol\Product\ClickOnceRunner\Release\ClickOnceRunner.pdb
An error has occurred. This application may no longer respond until reloaded. Reload 🗙